Senior Analyst Cybersecurity Risk & Compliance
Job Summary
The Cybersecurity Risk & Compliance function is responsible for identifying assessing and managing cybersecurity and compliance risks across the organization. The team establishes security standards validates adherence to security controls and partners with business and technology teams to strengthen the organizations security posture.
As a Senior Analyst in the Cybersecurity Risk & Compliance team you will independently execute cybersecurity risk assessments compliance reviews and governance activities while supporting the organizations evolving AI adoption. You will collaborate with Product Engineering Legal Privacy and business stakeholders to identify risks recommend appropriate controls and ensure security requirements are incorporated into business initiatives.
Role Expectations
Conduct cybersecurity risk assessments for products applications infrastructure vendors and business initiatives including New Product Initiatives (NPIs).
Perform AI governance reviews for AI/ML use cases GenAI integrations third-party AI services and agentic workflows by identifying potential security privacy and compliance risks.
Evaluate security risks and recommend appropriate controls aligned with organizational policies and industry best practices.
Support the implementation and operationalization of cybersecurity policies standards and control requirements across business and technology teams.
Partner with Product Engineering Cloud Privacy Legal and other stakeholders to provide practical security guidance throughout project lifecycles.
Assist with readiness activities for security certifications and compliance frameworks by collecting evidence validating controls and supporting internal and external audits.
Review the effectiveness of implemented security controls and track remediation activities through to closure.
Support continuous monitoring activities by maintaining risk registers dashboards metrics and compliance reporting.
Participate in security awareness initiatives by providing guidance on cybersecurity policies secure development practices and responsible AI usage.
Contribute to improving risk assessment methodologies governance processes templates and documentation.
Identify opportunities to automate repetitive risk and compliance activities to improve operational efficiency.
Stay current with emerging cybersecurity threats regulatory developments cloud security trends and AI governance practices.
Qualifications :
36 years of experience in Cybersecurity Risk & Compliance Information Security Governance Risk & Compliance (GRC) or related domains.
Experience conducting cybersecurity risk assessments security reviews compliance assessments or control validation activities.
Working knowledge of cloud security concepts preferably AWS and common cloud security controls.
Familiarity with cybersecurity frameworks such as ISO 27001 SOC 2 NIST CSF PCI DSS HIPAA NIST 800-171 or similar frameworks.
Exposure to AI governance concepts AI risk assessments or emerging AI security considerations is desirable.
Understanding of common AI/ML security risks including:
Data leakage
Prompt injection
Hallucination and model reliability
Third-party AI integrations
Bias and fairness considerations
Familiarity with software development and cloud technologies is desirable including:
AWS
Kubernetes
Docker
CI/CD pipelines
GitHub
Strong analytical and problem-solving skills with the ability to evaluate security risks and recommend practical solutions.
Excellent written and verbal communication skills with experience working across cross-functional teams.
Relevant certifications such as Security CISA CISM CRISC AWS Security Specialty or similar certifications are desirable.
Key Responsibilities
Independently execute cybersecurity and AI risk assessments.
Review business initiatives for compliance with security policies and standards.
Support audit readiness and evidence collection activities.
Perform security reviews for new technologies and third-party services.
Track remediation plans and validate control implementation.
Maintain governance documentation risk registers and assessment artifacts.
Provide day-to-day cybersecurity guidance to business and engineering teams.
Contribute to continuous improvement of governance processes and automation initiatives.
Additional Information :
At Freshworks we have fostered an environment that enables everyone to find their true potential purpose and passion welcoming colleagues of all backgrounds genders sexual orientations religions and ethnicities. We are committed to providing equal opportunity and believe that diversity in the workplace creates a more vibrant richer environment that boosts the goals of our employees communities and business. Fresh vision. Real impact. Come build it with us.
Remote Work :
No
Employment Type :
Full-time
About Company
Freshworks makes it fast and easy for businesses to delight their customers and employees. We do this by taking a fresh approach to building and delivering software that is affordable, quick to implement, and designed for the end user. Headquartered in San Mateo, California, Freshwork ... View more